Sun Java Runtime Environment Buffer Overflow in Applet Image Parsing Lets Remote Users Gain Privileges
|
|
SecurityTracker Alert ID: 1018182
|
|
SecurityTracker URL: http://securitytracker.com/id?1018182
|
|
CVE Reference: CVE-2007-3004
, CVE-2007-3005
(Links to External Site)
|
Updated: Jun 29 2007
|
Original Entry Date: Jun 1 2007
|
Impact: Denial of service via network, Disclosure of system information, Disclosure of user information, Execution of arbitrary code via network, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Sun Alert
|
Version(s): 1.3.1_20, 1.4.2_14, 5.0 Update 10; and prior versions; 6
|
Description: A vulnerability was reported in Sun Java Runtime Environment (JRE). A remote user can gain elevated privileges on the target user's system.
A remote user can create a specially crafted applet that, when loaded by the target user, will trigger a buffer overflow in the image
parsing code and gain elevated privileges. The applet can read and write local files or execute local applications with the privileges
of the target user.
A remote user can also cause the Java Virtual Machine to hang.
Chris Evans of the Google Security Team
reported this vulnerability.
|
Impact: A remote user can create a Java applet that, when loaded by the target user, will gain privileges on the target user's system.
A remote user can cause denial of service conditions.
|
Solution: Sun has issued the following fixes.
* JDK and JRE 6 Update 1 or later
* JDK and JRE 5.0 Update 11 or later
* SDK
and JRE 1.3.1_20 or later
Java SE 6 Update 1 is available for download at the following links:
* http://java.sun.com/javase/downloads/index.jsp
* http://java.com
Java SE 6 Update 1 for Solaris is available in the following patches:
* Java SE 6: update 1 (as delivered
in patch 125136-01)
* Java SE 6: update 1 (as delivered in patch 125137-01 (64bit))
* Java SE 6_x86: update 1 (as delivered
in patch 125138-01)
* Java SE 6_x86: update 1 (as delivered in patch 125139-01 (64bit))
J2SE 5.0 is available for download
at the following link:
* http://java.sun.com/j2se/1.5.0/download.jsp
J2SE 5.0 Update 11 for Solaris is available in the
following patches:
* J2SE 5.0: update 11 (as delivered in patch 118666-11)
* J2SE 5.0: update 11 (as delivered in patch
118667-11 (64bit))
* J2SE 5.0_x86: update 11 (as delivered in patch 118668-11)
* J2SE 5.0_x86: update 11 (as delivered
in patch 118669-11 (64bit))
SDK and JRE 1.4.2_15 is available for download at:
* http://java.sun.com/j2se/1.4.2/download.html
J2SE
1.3.1_20 is available for download at:
* http://java.sun.com/j2se/1.3/download.html
The Sun advisory is available at:
http://sunsolve.sun.com/search/document
.do?assetkey=1-26-102934-1
|
Vendor URL: sunsolve.sun.com/search/document.do?assetkey=1-26-102934-1 (Links to External Site)
|
Cause: Boundary error, State error
|
Underlying OS: Linux (Any), UNIX (Solaris - SunOS), Windows (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Thu, 31 May 2007 22:49:18 -0400
Subject: Security Vulnerabilities in the Java Runtime Environment Image Parsing Code may Allow a Untrusted Applet to Elevate Privileges
|
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102934-1
|
|